A website security audit in India can cost anywhere from nothing (a free automated scan) to several lakh rupees (a deep manual penetration test of a large application). Astra's published pricing guide puts a typical website security audit at roughly ₹35,000 to ₹1,50,000, with high-end penetration testing for regulated businesses at ₹3,00,000 to ₹7,00,000 a year. Most small business websites don't need the top end. They need the right scope.
This guide explains what you're actually paying for, so you can compare quotes fairly and avoid paying for a "VAPT certificate" that is only an automated scan with a logo on it.
What drives the cost of a website security audit?
- Size and complexity. A five-page brochure site is very different from an e-commerce store with customer accounts, a payment gateway, an admin panel and a mobile app API.
- Number of user roles. Each role (customer, vendor, staff, admin) has to be tested separately to check that one user can't see another's data. This is where serious bugs usually hide.
- Manual testing hours. Tools are cheap; skilled people's time is not. The share of manual testing is the biggest price difference between quotes.
- Black, grey or white box. Testing with no information (black box) is cheapest; testing with logins (grey box) or with source code access (white box) costs more but finds more.
- Compliance needs. Audits that must follow a regulator's format (RBI, SEBI, IRDAI, government "safe-to-host", PCI DSS) take more documentation and sometimes need a specific type of auditor.
- Retesting and support. Is a retest after you fix things included? Will they explain the fixes to your developer?
- Timeline. Urgent "we need a report by Friday" jobs cost more.
Typical price ranges in India (2026)
Prices vary a lot between providers, and very few publish them. The market figures below come from Astra's guide, one of the few vendors that publishes ranges; treat them as a rough guide, not a rate card. Our own prices are listed for comparison and are on our pricing page.
| Level | What you get | Good for | Typical cost |
|---|---|---|---|
| Free automated scan | Outside-in check of SSL, security headers, email records, outdated software and exposed files. | Every website, as a first step | Free (our scanner) |
| Automated report | Detailed scan report with prioritised, plain-English fixes. | Small sites, giving your developer a to-do list | Secuvexa: ₹799 |
| Small-business website audit | Scan plus manual review of configuration, CMS/plugins, login, forms and hosting setup. | Business sites, WordPress sites, small shops | Secuvexa: ₹4,999 (Starter) / ₹14,999 (Professional) |
| Comprehensive audit | Wider scope, more manual testing, compliance-oriented reporting. | Larger sites or stricter compliance needs | Market: ₹50,000–₹3,00,000 (Astra) |
| Web application VAPT | In-depth manual penetration testing of logins, roles, payments and APIs, plus retest. | E-commerce, fintech, portals holding sensitive data | Market: manual pentest phase ₹2,00,000–₹12,50,000; high-end ₹3,00,000–₹7,00,000/yr (Astra) |
Most quotes in India are exclusive of 18% GST, so check before comparing.
What does a small business actually need?
A sensible path for most small businesses is to go step by step and spend more only where the risk justifies it:
- Start with the free scan. It takes about 30 seconds and often finds easy wins: missing HTTPS redirect, no DMARC record, an old WordPress version, a forgotten
backup.zip. - Get the ₹799 report if you want a full, prioritised list to hand to your developer or hosting company.
- Book a ₹4,999 Starter audit if you run WordPress, take enquiries or orders, or store any customer details. A person checks what tools can't.
- Ask for a VAPT quote if you have customer logins, payments, an app or API, health or financial data, or a client/regulator is asking for a VAPT report. Tell us your scope and we'll quote in writing.
Red flags when buying a security audit or VAPT
- "Certificate in 24 hours" for a complex app. Real manual testing of a portal with several roles takes days.
- No written scope or authorisation letter. A professional tester always gets written permission and agrees exactly what is in and out of scope.
- The report is just tool output — hundreds of pages of copy-pasted scanner results with no proof, no business impact and no fix steps.
- "100% secure" or "hack-proof" promises. No honest tester says this.
- Asking for your passwords on WhatsApp or wanting full production admin access when a test account would do.
- Claimed empanelment you can't verify. If you need a CERT-In empanelled auditor, check the name on the official list at cert-in.org.in yourself. (Secuvexa is not CERT-In empanelled; we say so up front.)
- No retest included, so you never find out whether the fixes worked.
What a good security audit report contains
- Executive summary in plain language: overall risk, top three issues, what to do first.
- Scope and method: URLs, roles and dates tested, and what was not tested.
- Each finding with: a severity rating (e.g. Critical/High/Medium/Low), where it is, proof (screenshot or request/response), business impact and clear fix steps your developer can follow.
- False positives removed. A tester should verify findings, not paste every tool alert.
- Retest results showing which issues are now fixed.
- Confidential handling: the report itself is sensitive and should be shared securely.
How to get comparable quotes
Send every provider the same short brief: website URL, platform (WordPress, custom PHP, Laravel, Shopify, etc.), number of user roles, whether there's a payment gateway, app or API, any compliance requirement, and your deadline. Ask each one to state the number of manual testing days, whether a retest is included, the report format, and whether GST is extra. Then you're comparing like with like.
Based in Gujarat? See our page on VAPT and website security audits in Gujarat. Already seeing strange redirects or spam pages? Start with is my website hacked?
Frequently asked questions
What is the difference between a vulnerability scan and VAPT?
A scan uses automated tools to find known weaknesses and is quick and cheap. VAPT adds manual penetration testing, where a tester tries to actually exploit weaknesses such as broken login, payment or access controls that tools usually miss.
How long does a website VAPT take?
A small website is usually tested in a few working days, and a larger application with many roles and APIs can take two to three weeks, plus time for the report and a retest after you fix the issues.
Is GST extra on security audit prices?
Usually yes. Most quotes in India are given before 18% GST, so ask whether the price is inclusive or exclusive of GST before you compare.
Do I need a CERT-In empanelled auditor?
Only if a regulator, government department or client contract specifically asks for one. Many private businesses can use any competent tester; check the exact wording of the requirement first.
How often should a website be audited?
At least once a year and after any major change such as a new payment flow, login system or redesign. Automated scans can run monthly in between.
This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.